Penetration Testing
Details
- Published
- 29 September 2022
- Submission
- 13 October 2022
- Source
- uk:digital_marketplace
Tender description
Summary of the work As instructed by us, you'll conduct penetration tests in line with the NCSC CHECK approach on our various systems, both cloud based and on premise. Following each pentest, you'll produce a comprehensive report setting your findings and detailing risks discovered and providing advice for remediation or mitigation of such risks. Expected Contract Length 18 months (plus a possible 25%) Latest start date Monday 12 December 2022 Why the Work is Being Done As a responsible public body, we require a partner to provide penetration testing services to help assure the security of our systems. Problem to Be Solved Identify cybersecurity risks and vulnerabilities in our systems by conducting penetration tests. You will conduct penetration tests in line with the NCSC CHECK approach to provide security assurance and advice for the organisation. After any testing, you will produce a comprehensive report of your findings including outlining areas of risk, and providing advice for remediation or mitigation of such risks. Your pentest will be key in contributing to keeping systems safe and secure for the benefit of our customers and our staff. Who Are the Users The Financial Ombudsman Service was set up by Parliament in 2001 to resolve financial disputes. We can look at complaints about financial businesses and claims management companies, from consumers and small businesses, about a wide range of financial issues. You can find out more about the Financial Ombudsman Service on our website. Users of pentesting services will be our cyber security team and the teams supporting and developing our systems. These users will set the scope of pentests, work with your to determine a terms of reference and ways of working, review and act upon our findings. Early Market Engagement None. Work Already Done We expect you to follow the National Cyber Security Centre CHECK approach to penetration testing. Existing Team Our team comprises our cyber security team and the teams supporting and developing our systems. Current Phase Not applicable Skills & Experience • Must be National Cybersecurity Centre (NCSC) CHECK accredited. (Please provide evidence of being NCSC CHECK accredited.) • Must have recent experience pentesting a public facing web application hosted on Azure platform. (Outline a previous engagement where you pentested an example of the above. What, when, duration, result.) • Must understand the factors required for a successful pentest. (Please highlight a single factor that you believe has led to successful pentests in the past and explain why.) • Must have experience of deploying a capable team to deliver penetration testing. (Describe the indicative roles and team structure that you would typically use for a project like this.) • Must have experience of conducting a pentest that yielded unexpected results. (Describe what was unusual about the results, how you informed your client and the benefit to the client). Nice to Haves • Nice to have experience pentesting for an organisation similar to ours. (Describe experiences delivering penetration tests for organisations similar to the Ombudsman Service (type and size)). • Nice to have evidence of successful remote-working pentests. (Please describe your method for conducting remote-based pentests.) • Nice to have evidence of beneficial results for a client. (Please give an example of a recent pentest you have undertaken which proved insightful for a client and explain why.) Work Location The work is likely to be a mixture of remote-based and on-site work. When on-site work is required, this will take place at our London and/or Coventry offices. London offices: Exchange Tower, London, E14 9SR Coventry offices: 1 Friargate, Coventry, CV1 2GN Working Arrangments The work is likely to be a mixture of remote-based and on-site work. When on-site work is required, this will take place at our London and/or Coventry offices. Security Clearance Not required. Additional T&Cs A completed Call Off including Order Form will be shared with the shortlisted suppliers and form part of the additional assessment. No. of Suppliers to Evaluate 4 Proposal Criteria • How well the proposed solution meets requirements as set out in the work order and in the required timeline. (50%) • The proposed delivery approach and methodology (15%) • How the supplier identifies risks and dependencies and offered approaches to manage them (15%) • Sample Penetration Testing Findings Report (Quality and comprehensiveness) (10%) • Team structure (5%) • Case Study (5%) Cultural Fit Criteria • Take responsibility for delivering a successful service for the Ombudsman Service. • Be transparent and collaborative when communicating. • Be challenging of the Ombudsman Service where appropriate. • Have a no-blame culture and encourage people to learn from their mistakes • Share knowledge and experience with relevant team members. Payment Approach Time and materials Assessment Method • Case study • Presentation Evaluation Weighting Technical competence 60% Cultural fit 15% Price 25% Questions from Suppliers 1. Can the Authority please confirm whether there is an incumbent supplier? We do not currently have an incumbent supplier for these services. 2. Can the Authority please confirm the budget? We are not providing budget information at this stage. 3. Is there an expected budget for this work? We are not providing budget information at this stage. 4. Do you accept CREST approved penetration testing companies or must we be CHECK accredited? CHECK accreditation is mandatory for this requirement. 5. You mention we need to use the Check approach – however we have just started our process to become Check accredited – but we have been doing penetration for many years for many companies including local government, local authorities and are able to provide references. Would this be enough for us to be considered. We are already Crest accredited. We require the partner to be CHECK accredited. Unfortunely we are not able to progress with companies that are in the process of achieving accreditation on this occasion. 6. When stating 12/12/22 as a ‘start time’, is this date relating to the contractual commencement, or the targeted date of the first test? 12/12/22 is the anticipated start date of the contract with pentest activity commencing shortly after. This is the latest date, if we are able to start sooner we would take that opportunity. 7. Please can you confirm if CHECK accreditation is mandatory or if a CREST accreditation will be accepted? CHECK accreditation is mandatory for this requirement.
Timeline
- Completed: Tender published29 September 2022Current notice
- Completed: Submission date13 October 2022
About the buyer
Financial Ombudsman Service is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@financial-ombudsman-service.gov |
Related topics
Topics related to Penetration Testing, ranked by notice volume.
- 5,185£735.9bn
- 1,418£20.1bn
Related buyers
Buyers similar to Financial Ombudsman Service.
- 1,706£205.2bn
- 459£2.1bn
- 372£250.0m
- 359£15.0bn
- 293£2.8bn
- 267£19.9bn
- 249£511.2m
- 203£1.0bn
- 142£900.0m
- 122£59.9m
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
